Master Your
Attack Surface
The all-in-one, open-source reconnaissance platform. Visualize threats, track assets, and secure your infrastructure with cutting-edge precision β free for anyone to use, run, and improve.
Security Through Transparency
YADS provides deep insights into your digital presence, identifying vulnerabilities before they can be exploited.
Asset Discovery
Automatic detection of shadow IT, subdomains, and unknown cloud resources across all major providers.
Attack Paths
Visualize attacker movements from open ports to sensitive data using interactive D3.js graphs.
PQC Readiness
Prepare for the quantum era with automated CBOM generation and analysis of your cryptographic assets.
Hash-Chain Audit Logs
DORA-compliant tamper-proof audit trails using cryptographic chaining of every system action.
SLA Management
Automated remediation tracking with BSI-compliant deadlines for Critical, High, and Medium findings.
Encrypted BYOK
All sensitive integration keys are protected at rest with AES-256 (Bring Your Own Key security).
Platform Highlights
AI & Automation
AI Intelligence Assistant, AI-generated Finding Descriptions, and the AI Add-on Lab β grounded in your scan data, always with a human in the loop.
- π€ Conversational AI grounded in your findings
- π Auto-generate finding descriptions with fix steps
- π§ͺ Generate custom scanner modules from plain language
- β No autonomous deployment β human review always required
Visual Attack Paths
Identify complex vulnerability chains in real-time with granular analysis.
Cloud Asset Monitoring
Seamless integration for GCP, Azure, and AWS cloud infrastructures.
WAF Analysis Suite
Deep dive into Web Application Firewall logs for advanced bot detection.
Data Leak Monitor
Monitor darknet and paste sites for compromised credentials and data leaks.
Active Validation
Don't just find vulnerabilities β confirm they're still real. Purpose-built validators re-check individual findings on demand and return a verdict in seconds.
- β Not confirmed β finding likely resolved
- π΄ Confirmed β still exploitable right now
- π 7 built-in validators, zero configuration
- π Evidence persisted for audit & compliance (NIS2, DORA, ISO 27001)
AI-Scored Discovery
Interactive "Vibe Sessions" for asset discovery with AI relevance scoring and signal analysis.
Framework Trends
Track historical compliance progress against SOC2, GDPR, and NIS2 frameworks automatically.
TOGO Offline Hub
Export interactive, self-contained HTML/PDF reports for secure offline offline viewing or client delivery.
Worker Orchestration
Global worker node telemetry, load balancing, and multi-region scan orchestration for large-scale ops.
Module Signing
Cryptographic integrity verification for every add-on module via Ed25519 signatures.
Intelligence Hub
JARM TLS fingerprinting, Origin-IP WAF bypass detection, and Canary Token deployment β in one unified view.
What's New
Highlights since v4.5.8 β full changelog β
Backup & Restore Overhaul
Instance UUIDs are never overwritten during restore. Version compatibility check before import. Real-time progress bar.
AI Analysis & LLM Defaults
Default LLM provider selections for faster AI setup. Improved AI cleanup logic with hard-rule filtering for more reliable finding prioritization.
Import Findings Category
Findings imported from Nessus, Burp, OpenVAS, Qualys, ZAP and Nuclei now carry the imported category β filterable and included in PDF exports.
Settings & About Page
New About tab in Settings shows running version, edition, instance UUID and license info at a glance. Restore options now use granular keep/purge flags.
Contacts & Activations Pagination
Support portal contact and activation lists now paginate at 50 rows β eliminates memory pressure on large deployments.
Stability & Bug Fixes
Scanner module compatibility fixes, RabbitMQ consumer timeout raised to 70 min, sequence reset after restore, CSRF handling improvements.
Free & Open Source
YADS is fully open source β every feature, no license keys, no tiers. Grab the code, run it yourself, and help shape where it goes next.